First published: Mon Mar 25 2019(Updated: )
An issue existed in the handling of S-MIME certificates. This issue was addressed with improved validation of S-MIME certificates. This issue is fixed in macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra. Processing a maliciously crafted mail message may lead to S/MIME signature spoofing.
Credit: product-security@apple.com Maya Sigal Freie UniversitVolker Roth Freie Universit
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mac OS X | <10.14.4 | |
Apple macOS Mojave | <10.14.4 | 10.14.4 |
Apple High Sierra | ||
Apple Sierra |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID for this issue is CVE-2019-8642.
The severity of CVE-2019-8642 is medium with a CVSS score of 3.3.
The affected software includes Apple Mac OS X, macOS Mojave 10.14.4, Apple High Sierra, and Apple Sierra.
The vulnerability was fixed in macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, and Security Update 2019-002 Sierra.
You can find more information about CVE-2019-8642 on the Apple Support page: https://support.apple.com/en-us/HT209600